← Back to WayPoint

Privacy Policy

Elegibilidade (PT)

Plataforma exclusiva para pilotos com habilitação comercial ANAC válida (CPL, ATPL ou equivalente). A habilitação comercial exige, por lei, no mínimo 18 anos de idade. O cadastro de menores de 18 anos é vedado.

Eligibility (EN)

WayPoint is restricted to pilots holding a valid commercial ANAC license (CPL, ATPL or equivalent). A commercial license requires, by law, a minimum age of 18. Registration by users under 18 is not permitted.

How we handle your data (EN)

This is a summary. The full policy, which is the one that applies, is in Portuguese: Política de Privacidade. Last updated 29 September 2026.

  • We collect only what the service needs: your profile (name, photo, airline, position), your e-mail for login, your roster and flight hours, your country of residence and, only if you opt in, your medical class and citizenships for job eligibility.
  • Direct messages are encrypted in transit (HTTPS) and at rest (Supabase's encrypted database). Nobody at WayPoint reads them day to day: we access a message only to handle a report from another pilot or when a formal court order requires it. This replaces the earlier end-to-end encryption wording from 1 October 2026.
  • We never sell or rent personal data. We share it only with the services that run WayPoint: Supabase (database and login), Firebase (push notifications), Hostinger (the private server that hosts the app, in Frankfurt, Germany), Sentry (error reports, below), Resend (sending WayPoint's e-mails) and Google Gemini, with Ollama Cloud as a backup (reading roster images and PDFs in formats we cannot read yet, below), plus courts when a formal court order requires it. Our usage statistics (Umami) run on our own server and use no cookies.
  • Brazilian law (Marco Civil) requires us to keep access logs for 180 days, and login records for up to 365 days.
  • You can access, export, correct and delete your data in the app, or write to compliance@mywpoint.com.

Reading rosters with AI (Google Gemini and Ollama)

PDFs from airlines WayPoint already knows how to read are read by our own code, in your browser or on our server, with no AI. Otherwise we use third-party AI services to extract the flights: a roster image or screenshot you upload goes to Google Gemini (Google LLC, USA; processed outside Brazil, mainly in the USA), with Ollama Cloud (Ollama, USA) as a backup if Gemini fails; a PDF in a format we cannot read yet has up to about 30,000 characters of its text sent to Google Gemini. Only the airline, base and roster month go with it; we do not send your e-mail or account ID. A roster may contain your name and colleagues' names, times, hotels and notes printed by the airline. This happens only when you upload the file yourself. Legal basis: the service you asked for (LGPD art. 7, V); the transfer to the USA is needed to provide it (LGPD art. 33, IX).

Auto-Sync is off

WayPoint does not accept your airline crew-portal password. The "Auto-Sync" feature that asked for it never worked and was switched off on 28 September 2026; no portal password is stored. To bring your roster in, import your airline's official calendar link ("Calendar URL") where it offers one that needs no login, or upload the PDF, again whenever the roster changes. Any future airline integration will use the airline's own official login, so WayPoint never sees your password.

Garmin watch (optional)

You can connect a Garmin watch to see your next duties on it. It starts only when you confirm, signed in, the 6-digit code your watch shows. The watch receives your own next duties only (from 12 hours back to 7 days ahead): your airline's code, flight numbers, airports, report, departure and arrival times, aircraft type, the deadhead and instruction marks, duty codes, the first and last day of your days off or vacation, and the date your roster was uploaded. Nothing about other people: no names, no crew, no hotel. We keep the watch's model, when it was connected and last used, and an access key that belongs to that watch alone; the 6-digit code lasts 10 minutes and is deleted, with the watch's model and language that come with it, about an hour after it expires. Your data export lists the model and the dates, never the key. Every time a watch is connected to your account you get a notice in WayPoint (and on your phone, if notifications are on) with the way to disconnect it. Only connect a watch that is on your own wrist: if somebody sends you a pairing link or a code, do not confirm it. The watch keeps its key and the last answer it received, and talks to WayPoint through the Garmin Connect app on your phone, a Garmin product under Garmin's own privacy policy. Disconnect it in Settings > Tools > Garmin watch or from the watch's menu: the key stops working at once. It also expires 180 days after its last use, and connecting another watch disconnects the previous one. Legal basis: the service you asked for (LGPD art. 7, V).

Error monitoring (Sentry), from 21 September 2026

To find and fix bugs, WayPoint uses Sentry, a service of Functional Software, Inc. (USA), with our data stored in Frankfurt, Germany (EU). When something breaks in your browser or on our servers, we send an error report: the error message and technical stack trace, the page address (with profile handles, conversation IDs and access codes removed), the last few technical steps before the error (pages opened, network calls and their status, console warnings and errors), browser, operating system and device type, the app version, and your WayPoint account ID. We do not send your name, e-mail, IP address, cookies, message contents or form contents, and we do not record your screen. This uses no cookies. Legal basis: our legitimate interest in keeping WayPoint secure and working (LGPD art. 7, IX; GDPR art. 6(1)(f)). Reports are deleted automatically after 30 days. Sentry processes this data only on our instructions under its Data Processing Addendum; Sentry may access it from the US for support and security. You can switch error reports off on your device in Settings > Privacy, or object at compliance@mywpoint.com. This starts on 21 September 2026, 7 days after we announced it.

Optional test recording

Beta testers we invite may choose to let us record their sessions (pages, clicks and scrolling, with all on-screen text, images and typing masked, and direct messages never recorded) to reproduce bugs. Recording starts only after the tester agrees on a dedicated screen, shows a visible "Recording" badge, can be stopped at any time in Settings > Privacy (at once on the device used, within a minute on the tester's other devices), and recordings are deleted after 30 days or sooner on request. Legal basis: consent (LGPD art. 7, I and art. 33, VIII; GDPR art. 6(1)(a)). No other member is ever recorded.